2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-9417HIGH8.8A weakness has been identified in itsourcecode Apartment Management System 1.0. This issue affects some unknown processi...
CVE-2025-57811HIGH7.2Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is...
CVE-2025-57802HIGH8.7Airlink's Daemon interfaces with Docker and the Panel to provide secure access for controlling instances via the Panel. ...
CVE-2025-50383HIGH8.1alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by paramet...
CVE-2025-6737HIGH7.2Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenan...
CVE-2025-57760HIGH8.8Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exis...
CVE-2025-29421HIGH7.5PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.
CVE-2025-29420HIGH7.5PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.
CVE-2025-55409HIGH8.8FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows attackers to execute arbi...
CVE-2025-53119HIGH7.5An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious binaries and scripts to...
CVE-2025-3478HIGH8.5A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Enterprise Security Manager. The vulne...
CVE-2025-29523HIGH7.2D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability vi...
CVE-2025-5302HIGH8.6A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifical...
CVE-2025-56216HIGH8.5phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter.
CVE-2025-53510HIGH8.8A memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9...
CVE-2025-53085HIGH8.8A memory corruption vulnerability exists in the PSD RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8...
CVE-2025-52930HIGH8.8A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9...
CVE-2025-52456HIGH8.8A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0....
CVE-2025-51281HIGH7D-Link DI-8100 16.07.26A1 is vulnerable to Buffer Overflow via the en`, `val and id parameters in the qj_asp function. T...
CVE-2025-50129HIGH8.8A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9...
CVE-2025-46407HIGH8.8A memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library ...
CVE-2025-35984HIGH8.8A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9...
CVE-2025-32468HIGH8.8A memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0...
CVE-2025-54370HIGH8.7PhpOffice/PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to versions 1.30.0, 2.1....
CVE-2025-43960HIGH8.6Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now